spf-discuss
[Top] [All Lists]

RE: Attacking Domain Keys

2004-11-29 19:42:25

As is the implementation of any other algorithm.  RSA 
signature validation is a very CPU-intensive algorithm that 
unfairly burdens the recipient. HMAC-SHA1 signatures are much 
faster, and you can optimize both to your heart's content and 
still come up with the same result.

How do trolls perform the necessary key distribution?

If you understood what HMAC is then you would know why it is completely
impractical for this application, the authentication key must be shared
between sender and receiver. 


<Prev in Thread] Current Thread [Next in Thread>